This message was deleted.
# puppet-enterprise
s
This message was deleted.
c
No, those files need to be copied from the original server. Although, there's no real loss if SSH/WinRM credentials or a SAML integration is not in use.
b
SSH/WinRM/SAML wasn't used, just AD integration (and we manage that with a puppet resource)
what is the keys.json used for in the orchestrator/console-services directory?
and the orchestrator-encryption-keys.json?
c
The Orchestrator key provides encryption-at-rest for SSH private keys and WinRM passwords stored in Postgres.
b
ahh
c
The Console key does the same for the credentials used to bind with LDAP or integrate with SAML.
b
we can probably hack the script from https://www.puppet.com/docs/pe/2021.7/rotating_inventory_service_secret_key.html#rotating-inventory-service-secret-key and use it for the console-services as well?
c
Maybe. Both services are using the same Postgres functionality, but the implementation paths might be different. @jonathan.newman What's the best way to rotate or clear Console LDAP credentials if the encryption key was lost?
b
and how is orchestrator-encryption-keys.json used? that's not updated by the script, just the keys.json
s
When the RBAC service starts up, if the encryption key is not present, itโ€™ll just generate a new one. Then you can re-enter LDAP settings
b
and if there are already LDAP settings in the DB? Will it generate a new a new key but unable to read existing settings in the DB? do we need to purge anything in the DB?
we were not able to configure the LDAP settings via the API, but I had no time to investigate today
s
Yeah, it will not be able to read the stored creds - there will probably be some log entries around that. For replacing, you should be able to just
PUT /ds
with the new settings
b
mhm it probably failed because the puooet reaource first does a GET to check the current config
will give that a try tomorrow, thanks!
s
๐Ÿ‘
b
It doesn't look like I can update the LDAP config when there is old data in the database that' encrypted with another key. console-services log says:
Copy code
2023-04-20T09:10:31.309+02:00 [qtp751524958-41576] WARN  [p.r.h.middleware] PUT /rbac-api/v1/ds
org.postgresql.util.PSQLException: ERROR: Wrong key or corrupt data
during the PUT request
s
hmmm, did you try putting an empty object first to clear?
j
What version of PE is this? We might have to resort to direct DB manipulation to resolve it.
b
It is 2021.7.2
@steveax oh! We only tried to PUT a new config, not an empty one
in the meantime someone found the old keys in a backup, so we are good now. but maybe it would be helpful to update the maintenance page that has orchestrator key rotation with console services recovery as well
๐Ÿ‘ 1
s
I know it is intentional these keys are not part of a PE Backup. But an option like
--yesiwanttobackupsecrets
would be awesome
๐Ÿ‘ 1